Forensics
Disk, memory, and timeline tooling for evidence-first investigations.
-
Autopsy App
Open-source GUI that layers Sleuth Kit modules for rapid triage, artifact discovery, and cross-case correlation—ideal for combining timeline, registry, and mobile data in one review pane.
-
FTK Imager
Lightweight acquisition utility that captures pristine disk images, volatile memory, and logical files while validating hashes, making it perfect for courtroom-ready collections from compromised hosts.